CVE-2026-14456

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/08/2026
Last modified:
28/08/2026

Description

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes<br /> valid QUIC Initial packets for unknown destination connection IDs, it<br /> can allocate and queue new incoming channels without enforcing any limit.<br /> <br /> Impact summary: A remote peer that can make many Initial packets reach the<br /> server listener faster than the application accepts connections, can cause the<br /> memory allocated to store the per-channel state to grow without any limits,<br /> potentially making the QUIC listener unavailable and causing Denial of Service.<br /> <br /> CWE: CWE-770: Allocation of Resources Without Limits or Throttling<br /> <br /> Description: The function that handles inbound QUIC packets uses<br /> Connection-Id from the packet header to find an existing connection<br /> (QUIC channel). If no existing connection is found and the packet<br /> type is INITIAL, the function treats the packet as a new connection. It<br /> allocates a new channel object and inserts it into a queue where it<br /> waits to be accepted by the local application with SSL_accept(3ossl).<br /> The memory occupied by these initial channel objects may grow<br /> without bounds if the application is not able to call SSL_accept()<br /> frequently enough to serve these inbound connection requests.<br /> <br /> The issue is present since OpenSSL 3.5 when the QUIC server implementation<br /> was added.<br /> <br /> The fix introduces a limit for pending connections. The default limit is set<br /> to 256 pending connections (waiting to be accepted by the local application).<br /> Applications may change the default by calling SSL_set_value_uint(3ossl).<br /> <br /> FIPS impact: no<br /> The FIPS module is not affected as the QUIC implementation is outside of<br /> the OpenSSL FIPS module boundary.